Resume and JobRESUME AND JOB
DocuSign logo

Technical Security Governance Manager

DocuSign

Engineering Jobs

Technical Security Governance Manager

full-timePosted: Oct 8, 2025

Job Description

Technical Security Governance Manager

Location: Bengaluru, India

Department: Security

Work Mode: Hybrid

About the Role

Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate business processes and simplify lives through intelligent agreement management. As the #1 company in e-signature and contract lifecycle management (CLM), we unleash business-critical data trapped in documents, connecting it to systems of record to drive efficiency and innovation. Join our pioneering security team to safeguard these mission-critical platforms. The Technical Security Governance Manager plays a pivotal role in evolving our governance model from policy-driven to technically prescriptive, blending deep governance knowledge with hands-on technical acumen. You will ensure security policies and controls for our e-signature and CLM solutions are implementable, measurable, and effective—protecting customer trust while enabling secure innovation at scale. Reporting to the Director of Security Governance as an individual contributor, you will define controls, translate policies into engineering requirements, and integrate governance into CI/CD pipelines and infrastructure, collaborating closely with engineering, compliance, and risk teams to boost control adoption, fortify our security posture, and minimize friction between intent and execution. This hybrid role (minimum 2 days/week in-office) thrives in DocuSign's innovative culture, where bold ideas and collaboration fuel breakthroughs in digital agreements. You'll leverage security frameworks like ISO 27001, SOC 2, NIST, PCI DSS, and FedRAMP to align with regulatory demands, utilize GRC tools for visibility, and drive DevSecOps practices that empower engineers without slowing velocity. If you're a proactive self-starter passionate about translating risk into actionable tech steps, join us to make the world more agreeable—and more secure. At Docusign, everything is equal. We're committed to trust, honesty, and equal opportunity, fostering an environment where every voice contributes to world-changing work. Feel deep pride knowing your security expertise protects billions of agreements daily.

Key Responsibilities

  • Support the development, maintenance, and refinement of enterprise-wide security policies, standards, and control objectives for DocuSign's Intelligent Agreement Management platform
  • Align policies with key frameworks (e.g., ISO 27001, SOC 2, NIST CSF, PCI DSS, FedRAMP) and regulatory requirements to protect e-signature and CLM solutions
  • Keep security policies and standards current, practical, and risk-aligned with evolving threats in digital agreement workflows
  • Define and document implementable, measurable controls incorporating both policy and technical input from engineering teams
  • Partner with engineering to embed security controls into CI/CD pipelines, infrastructure-as-code, and operational processes supporting DocuSign's global customer base
  • Support policy education and adoption programs to drive awareness and compliance across engineering, product, and compliance organizations
  • Design processes integrating policy-driven controls into DevSecOps practices and engineering ways of working
  • Collaborate with compliance and risk teams to track, monitor, and report on control effectiveness using metrics tied to security posture
  • Utilize technical tooling (e.g., GRC systems, automation dashboards) to provide real-time visibility into control implementation and e-signature platform security
  • Participate in technical assurance efforts to proactively identify implementation gaps and prevent audit findings in high-stakes environments
  • Contribute to cross-functional initiatives enhancing security innovation while reducing friction between governance and technical execution

Required Qualifications

  • 5+ years of experience in security governance, GRC, or security engineering, with at least 3 years in a technical security role
  • University degree in Computer Science, Information Systems, or related field, or equivalent work experience
  • Knowledge of security frameworks and standards (e.g., ISO 27001, SOC 2, NIST CSF, PCI DSS, FedRAMP)
  • Demonstrated experience defining and embedding security controls into engineering workflows, CI/CD pipelines, or infrastructure
  • Familiarity with security tooling, GRC platforms, and automation frameworks
  • Strong understanding of information security concepts, processes, and controls
  • Proven ability to translate policy and risk requirements into actionable technical steps for engineering teams

Preferred Qualifications

  • One or more certifications such as Security+, CISA, CISM, or CISSP
  • Experience working in cloud environments (AWS, GCP, Azure) with exposure to infrastructure-as-code practices
  • Understanding of DevSecOps, security automation, and control validation techniques
  • Experience supporting cross-functional initiatives involving engineering, compliance, and product teams
  • Proactive self-starter with demonstrated flexibility and organizational skills in fast-paced environments

Required Skills

  • Security governance and GRC expertise
  • Technical security engineering background
  • Knowledge of ISO 27001, SOC 2, NIST CSF, PCI DSS, FedRAMP
  • CI/CD pipeline integration and security control embedding
  • Infrastructure-as-code (IaC) practices
  • Cloud platforms (AWS, GCP, Azure)
  • DevSecOps and security automation
  • GRC platforms and security tooling
  • Policy translation to technical requirements
  • Cross-functional collaboration with engineering and compliance
  • Strong documentation and reporting
  • Excellent communication for technical and non-technical audiences
  • Proactive problem-solving and self-starter mindset
  • Risk assessment and control validation
  • Adaptability to emerging security threats

Benefits

  • Competitive salary and equity in a leading SaaS innovator
  • Comprehensive health, dental, and vision insurance
  • 401(k) matching and employee stock purchase plan
  • Unlimited PTO and flexible hybrid work model (minimum 2 days/week in-office)
  • Professional development stipend and certification reimbursement
  • Parental leave and family-forming benefits
  • Wellness programs including mental health support
  • Volunteer time off and community impact initiatives
  • DocuSign Cares Fund for employee hardship support

DocuSign is an Equal Opportunity Employer.

Locations

  • Cherry Hills Block Embassy Golf Links Business Park Challaghatta, Bengaluru, Karnataka, India 560071

Salary

Estimated Salary Rangemedium confidence

3,500,000 - 6,500,000 INR / yearly

Source: ai estimated

* This is an estimated range based on market data and may vary based on experience and qualifications.

Skills Required

  • Security governance and GRC expertiseintermediate
  • Technical security engineering backgroundintermediate
  • Knowledge of ISO 27001, SOC 2, NIST CSF, PCI DSS, FedRAMPintermediate
  • CI/CD pipeline integration and security control embeddingintermediate
  • Infrastructure-as-code (IaC) practicesintermediate
  • Cloud platforms (AWS, GCP, Azure)intermediate
  • DevSecOps and security automationintermediate
  • GRC platforms and security toolingintermediate
  • Policy translation to technical requirementsintermediate
  • Cross-functional collaboration with engineering and complianceintermediate
  • Strong documentation and reportingintermediate
  • Excellent communication for technical and non-technical audiencesintermediate
  • Proactive problem-solving and self-starter mindsetintermediate
  • Risk assessment and control validationintermediate
  • Adaptability to emerging security threatsintermediate

Required Qualifications

  • 5+ years of experience in security governance, GRC, or security engineering, with at least 3 years in a technical security role (experience)
  • University degree in Computer Science, Information Systems, or related field, or equivalent work experience (experience)
  • Knowledge of security frameworks and standards (e.g., ISO 27001, SOC 2, NIST CSF, PCI DSS, FedRAMP) (experience)
  • Demonstrated experience defining and embedding security controls into engineering workflows, CI/CD pipelines, or infrastructure (experience)
  • Familiarity with security tooling, GRC platforms, and automation frameworks (experience)
  • Strong understanding of information security concepts, processes, and controls (experience)
  • Proven ability to translate policy and risk requirements into actionable technical steps for engineering teams (experience)

Preferred Qualifications

  • One or more certifications such as Security+, CISA, CISM, or CISSP (experience)
  • Experience working in cloud environments (AWS, GCP, Azure) with exposure to infrastructure-as-code practices (experience)
  • Understanding of DevSecOps, security automation, and control validation techniques (experience)
  • Experience supporting cross-functional initiatives involving engineering, compliance, and product teams (experience)
  • Proactive self-starter with demonstrated flexibility and organizational skills in fast-paced environments (experience)

Responsibilities

  • Support the development, maintenance, and refinement of enterprise-wide security policies, standards, and control objectives for DocuSign's Intelligent Agreement Management platform
  • Align policies with key frameworks (e.g., ISO 27001, SOC 2, NIST CSF, PCI DSS, FedRAMP) and regulatory requirements to protect e-signature and CLM solutions
  • Keep security policies and standards current, practical, and risk-aligned with evolving threats in digital agreement workflows
  • Define and document implementable, measurable controls incorporating both policy and technical input from engineering teams
  • Partner with engineering to embed security controls into CI/CD pipelines, infrastructure-as-code, and operational processes supporting DocuSign's global customer base
  • Support policy education and adoption programs to drive awareness and compliance across engineering, product, and compliance organizations
  • Design processes integrating policy-driven controls into DevSecOps practices and engineering ways of working
  • Collaborate with compliance and risk teams to track, monitor, and report on control effectiveness using metrics tied to security posture
  • Utilize technical tooling (e.g., GRC systems, automation dashboards) to provide real-time visibility into control implementation and e-signature platform security
  • Participate in technical assurance efforts to proactively identify implementation gaps and prevent audit findings in high-stakes environments
  • Contribute to cross-functional initiatives enhancing security innovation while reducing friction between governance and technical execution

Benefits

  • general: Competitive salary and equity in a leading SaaS innovator
  • general: Comprehensive health, dental, and vision insurance
  • general: 401(k) matching and employee stock purchase plan
  • general: Unlimited PTO and flexible hybrid work model (minimum 2 days/week in-office)
  • general: Professional development stipend and certification reimbursement
  • general: Parental leave and family-forming benefits
  • general: Wellness programs including mental health support
  • general: Volunteer time off and community impact initiatives
  • general: DocuSign Cares Fund for employee hardship support

Target Your Resume for "Technical Security Governance Manager" , DocuSign

Get personalized recommendations to optimize your resume specifically for Technical Security Governance Manager. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "Technical Security Governance Manager" , DocuSign

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

DocuSignSaaSSecurityBengaluruIndiaSecurity

Answer 10 quick questions to check your fit for Technical Security Governance Manager @ DocuSign.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.

DocuSign logo

Technical Security Governance Manager

DocuSign

Engineering Jobs

Technical Security Governance Manager

full-timePosted: Oct 8, 2025

Job Description

Technical Security Governance Manager

Location: Bengaluru, India

Department: Security

Work Mode: Hybrid

About the Role

Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate business processes and simplify lives through intelligent agreement management. As the #1 company in e-signature and contract lifecycle management (CLM), we unleash business-critical data trapped in documents, connecting it to systems of record to drive efficiency and innovation. Join our pioneering security team to safeguard these mission-critical platforms. The Technical Security Governance Manager plays a pivotal role in evolving our governance model from policy-driven to technically prescriptive, blending deep governance knowledge with hands-on technical acumen. You will ensure security policies and controls for our e-signature and CLM solutions are implementable, measurable, and effective—protecting customer trust while enabling secure innovation at scale. Reporting to the Director of Security Governance as an individual contributor, you will define controls, translate policies into engineering requirements, and integrate governance into CI/CD pipelines and infrastructure, collaborating closely with engineering, compliance, and risk teams to boost control adoption, fortify our security posture, and minimize friction between intent and execution. This hybrid role (minimum 2 days/week in-office) thrives in DocuSign's innovative culture, where bold ideas and collaboration fuel breakthroughs in digital agreements. You'll leverage security frameworks like ISO 27001, SOC 2, NIST, PCI DSS, and FedRAMP to align with regulatory demands, utilize GRC tools for visibility, and drive DevSecOps practices that empower engineers without slowing velocity. If you're a proactive self-starter passionate about translating risk into actionable tech steps, join us to make the world more agreeable—and more secure. At Docusign, everything is equal. We're committed to trust, honesty, and equal opportunity, fostering an environment where every voice contributes to world-changing work. Feel deep pride knowing your security expertise protects billions of agreements daily.

Key Responsibilities

  • Support the development, maintenance, and refinement of enterprise-wide security policies, standards, and control objectives for DocuSign's Intelligent Agreement Management platform
  • Align policies with key frameworks (e.g., ISO 27001, SOC 2, NIST CSF, PCI DSS, FedRAMP) and regulatory requirements to protect e-signature and CLM solutions
  • Keep security policies and standards current, practical, and risk-aligned with evolving threats in digital agreement workflows
  • Define and document implementable, measurable controls incorporating both policy and technical input from engineering teams
  • Partner with engineering to embed security controls into CI/CD pipelines, infrastructure-as-code, and operational processes supporting DocuSign's global customer base
  • Support policy education and adoption programs to drive awareness and compliance across engineering, product, and compliance organizations
  • Design processes integrating policy-driven controls into DevSecOps practices and engineering ways of working
  • Collaborate with compliance and risk teams to track, monitor, and report on control effectiveness using metrics tied to security posture
  • Utilize technical tooling (e.g., GRC systems, automation dashboards) to provide real-time visibility into control implementation and e-signature platform security
  • Participate in technical assurance efforts to proactively identify implementation gaps and prevent audit findings in high-stakes environments
  • Contribute to cross-functional initiatives enhancing security innovation while reducing friction between governance and technical execution

Required Qualifications

  • 5+ years of experience in security governance, GRC, or security engineering, with at least 3 years in a technical security role
  • University degree in Computer Science, Information Systems, or related field, or equivalent work experience
  • Knowledge of security frameworks and standards (e.g., ISO 27001, SOC 2, NIST CSF, PCI DSS, FedRAMP)
  • Demonstrated experience defining and embedding security controls into engineering workflows, CI/CD pipelines, or infrastructure
  • Familiarity with security tooling, GRC platforms, and automation frameworks
  • Strong understanding of information security concepts, processes, and controls
  • Proven ability to translate policy and risk requirements into actionable technical steps for engineering teams

Preferred Qualifications

  • One or more certifications such as Security+, CISA, CISM, or CISSP
  • Experience working in cloud environments (AWS, GCP, Azure) with exposure to infrastructure-as-code practices
  • Understanding of DevSecOps, security automation, and control validation techniques
  • Experience supporting cross-functional initiatives involving engineering, compliance, and product teams
  • Proactive self-starter with demonstrated flexibility and organizational skills in fast-paced environments

Required Skills

  • Security governance and GRC expertise
  • Technical security engineering background
  • Knowledge of ISO 27001, SOC 2, NIST CSF, PCI DSS, FedRAMP
  • CI/CD pipeline integration and security control embedding
  • Infrastructure-as-code (IaC) practices
  • Cloud platforms (AWS, GCP, Azure)
  • DevSecOps and security automation
  • GRC platforms and security tooling
  • Policy translation to technical requirements
  • Cross-functional collaboration with engineering and compliance
  • Strong documentation and reporting
  • Excellent communication for technical and non-technical audiences
  • Proactive problem-solving and self-starter mindset
  • Risk assessment and control validation
  • Adaptability to emerging security threats

Benefits

  • Competitive salary and equity in a leading SaaS innovator
  • Comprehensive health, dental, and vision insurance
  • 401(k) matching and employee stock purchase plan
  • Unlimited PTO and flexible hybrid work model (minimum 2 days/week in-office)
  • Professional development stipend and certification reimbursement
  • Parental leave and family-forming benefits
  • Wellness programs including mental health support
  • Volunteer time off and community impact initiatives
  • DocuSign Cares Fund for employee hardship support

DocuSign is an Equal Opportunity Employer.

Locations

  • Cherry Hills Block Embassy Golf Links Business Park Challaghatta, Bengaluru, Karnataka, India 560071

Salary

Estimated Salary Rangemedium confidence

3,500,000 - 6,500,000 INR / yearly

Source: ai estimated

* This is an estimated range based on market data and may vary based on experience and qualifications.

Skills Required

  • Security governance and GRC expertiseintermediate
  • Technical security engineering backgroundintermediate
  • Knowledge of ISO 27001, SOC 2, NIST CSF, PCI DSS, FedRAMPintermediate
  • CI/CD pipeline integration and security control embeddingintermediate
  • Infrastructure-as-code (IaC) practicesintermediate
  • Cloud platforms (AWS, GCP, Azure)intermediate
  • DevSecOps and security automationintermediate
  • GRC platforms and security toolingintermediate
  • Policy translation to technical requirementsintermediate
  • Cross-functional collaboration with engineering and complianceintermediate
  • Strong documentation and reportingintermediate
  • Excellent communication for technical and non-technical audiencesintermediate
  • Proactive problem-solving and self-starter mindsetintermediate
  • Risk assessment and control validationintermediate
  • Adaptability to emerging security threatsintermediate

Required Qualifications

  • 5+ years of experience in security governance, GRC, or security engineering, with at least 3 years in a technical security role (experience)
  • University degree in Computer Science, Information Systems, or related field, or equivalent work experience (experience)
  • Knowledge of security frameworks and standards (e.g., ISO 27001, SOC 2, NIST CSF, PCI DSS, FedRAMP) (experience)
  • Demonstrated experience defining and embedding security controls into engineering workflows, CI/CD pipelines, or infrastructure (experience)
  • Familiarity with security tooling, GRC platforms, and automation frameworks (experience)
  • Strong understanding of information security concepts, processes, and controls (experience)
  • Proven ability to translate policy and risk requirements into actionable technical steps for engineering teams (experience)

Preferred Qualifications

  • One or more certifications such as Security+, CISA, CISM, or CISSP (experience)
  • Experience working in cloud environments (AWS, GCP, Azure) with exposure to infrastructure-as-code practices (experience)
  • Understanding of DevSecOps, security automation, and control validation techniques (experience)
  • Experience supporting cross-functional initiatives involving engineering, compliance, and product teams (experience)
  • Proactive self-starter with demonstrated flexibility and organizational skills in fast-paced environments (experience)

Responsibilities

  • Support the development, maintenance, and refinement of enterprise-wide security policies, standards, and control objectives for DocuSign's Intelligent Agreement Management platform
  • Align policies with key frameworks (e.g., ISO 27001, SOC 2, NIST CSF, PCI DSS, FedRAMP) and regulatory requirements to protect e-signature and CLM solutions
  • Keep security policies and standards current, practical, and risk-aligned with evolving threats in digital agreement workflows
  • Define and document implementable, measurable controls incorporating both policy and technical input from engineering teams
  • Partner with engineering to embed security controls into CI/CD pipelines, infrastructure-as-code, and operational processes supporting DocuSign's global customer base
  • Support policy education and adoption programs to drive awareness and compliance across engineering, product, and compliance organizations
  • Design processes integrating policy-driven controls into DevSecOps practices and engineering ways of working
  • Collaborate with compliance and risk teams to track, monitor, and report on control effectiveness using metrics tied to security posture
  • Utilize technical tooling (e.g., GRC systems, automation dashboards) to provide real-time visibility into control implementation and e-signature platform security
  • Participate in technical assurance efforts to proactively identify implementation gaps and prevent audit findings in high-stakes environments
  • Contribute to cross-functional initiatives enhancing security innovation while reducing friction between governance and technical execution

Benefits

  • general: Competitive salary and equity in a leading SaaS innovator
  • general: Comprehensive health, dental, and vision insurance
  • general: 401(k) matching and employee stock purchase plan
  • general: Unlimited PTO and flexible hybrid work model (minimum 2 days/week in-office)
  • general: Professional development stipend and certification reimbursement
  • general: Parental leave and family-forming benefits
  • general: Wellness programs including mental health support
  • general: Volunteer time off and community impact initiatives
  • general: DocuSign Cares Fund for employee hardship support

Target Your Resume for "Technical Security Governance Manager" , DocuSign

Get personalized recommendations to optimize your resume specifically for Technical Security Governance Manager. Takes only 15 seconds!

AI-powered keyword optimization
Skills matching & gap analysis
Experience alignment suggestions

Check Your ATS Score for "Technical Security Governance Manager" , DocuSign

Find out how well your resume matches this job's requirements. Get comprehensive analysis including ATS compatibility, keyword matching, skill gaps, and personalized recommendations.

ATS compatibility check
Keyword optimization analysis
Skill matching & gap identification
Format & readability score

Tags & Categories

DocuSignSaaSSecurityBengaluruIndiaSecurity

Answer 10 quick questions to check your fit for Technical Security Governance Manager @ DocuSign.

Quiz Challenge
10 Questions
~2 Minutes
Instant Score

Related Books and Jobs

No related jobs found at the moment.